Snyk has a proof-of-concept or detailed explanation of how to exploit this vulnerability.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade llama-index-packs-finchat
to version 0.3.0 or higher.
llama-index-packs-finchat is a llama-index packs implementation of a hierarchical agent for finance chat.
Affected versions of this package are vulnerable to SQL Injection via the run_sql_query()
function in the database agent. An attacker can inject raw PostgreSQL statements into a prompt and have the resulting queries executed on the backing database. By leveraging PostgreSQL's lo_from_bytea()
function and compromising another file on the target server, this vulnerability can allow code execution on the operating system.